Skip to content

release.yml: once a version's fixed group is on npm, the push-lane Releases backfill races the publish job's own Releases step — 17.6.0 got 9 × 422 already_exists, 5 duplicate GitHub Releases and two red runs #21313

Description

@objectstack-fleet

Filed by the domain:cli seat (session_01VvcEokUG1tvVxkceYfR5XB) on the maintainer's direct instruction in that session on 2026-10-02: 「这次 Release 任务的结论是 failure,失败在 "Create GitHub Releases" 这一步。 报 issue」. ⛔ Not a claim, not a dispatch. Triage sets domain:* and the grade.

What happened (measured from the run logs and the Releases API)

The 17.6.0 release, cut from the version commit 617f25f8a4 (#20639), went to npm and pushed its tags cleanly. Two red runs followed, and they wrote to the same GitHub Releases at the same time:

Writer Run / job Script window Result
Publish job, step "Create GitHub Releases" run 36955885276, job 110678824190 03:03:47Z → 03:05:42Z 65 created, 1 updated, 3 failed (422)
Push-lane release-integrity, step "Backfill GitHub Releases" (the landing push 4e530568a2) run 36958423332, job 110686494582 03:04:37Z → 03:05:42Z 9 created, 54 updated, 6 failed (422)
  • Both run scripts/release-github-releases.mjs for RELEASE_VERSION: 17.6.0. They walk the package list in the same order, about 50 s apart, and catch up with each other near the tail of the list.
  • The 9 failures: every one is 422 {"code":"already_exists","field":"tag_name"}.
    • The publish job failed on service-messaging, trigger-record-change and trigger-schedule.
    • The backfill failed on service-job, service-package, service-queue, service-settings, service-sms and verify.
  • Duplicates: where both writers' check-then-create landed inside the same second, both POSTs succeeded. 69 tags now carry 74 Release objects. Five tags have two releases each, published within a second of each other:
    • @objectstack/service-knowledge@17.6.0: 401511494, 401511496
    • @objectstack/service-realtime@17.6.0: 401511528, 401511529
    • @objectstack/service-storage@17.6.0: 401511561, 401511562
    • @objectstack/spec@17.6.0: 401511580, 401511585
    • @objectstack/types@17.6.0: 401511638, 401511640
  • The ADR-0087 D4 asset: the publish job then ran release-spec-changes.sh --attach ("Attached spec-changes.json to release @objectstack/spec@17.6.0"). It landed on 401511580, and the other spec release, 401511585, carries no asset.

Why (read from release.yml at origin/main)

Current state

  • npm: all 69 packages are published at 17.6.0, and every tag is pushed.
  • GitHub Releases: every tag has at least one release.
    • Five tags have a duplicate.
    • The spec duplicate pair carries the D4 asset on only one of the two.
    • The releases/latest pointer reads @objectstack/verify@17.6.0.
  • Runs: both are red with no missing artifact.
  • Out of scope: the seat did not touch any release object. ⛔ Deleting the duplicate releases and re-running either job are release-surface actions, and they stay with the maintainer or the release lane.

Direction (for triage; not a ruling)

  • Exclusion: make the backfill and the publish job's Releases step mutually exclusive for one version. Either they share a concurrency group keyed on the version, or the push lane skips the Releases backfill while a publish run for that version has not concluded.
  • Idempotent script: make release-github-releases.mjs idempotent under a racing writer. On a 422 already_exists, re-read the tag's release and update it instead of failing.
  • Duplicates: decide whether the script also has to detect and report duplicate releases for a tag. The five above say the platform will not prevent them.
  • One-time cleanup: delete one release from each duplicate pair, keeping 401511580 for spec because it carries the D4 asset. This is the maintainer's call.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:specpriority:p2Medium: important, M3tooling

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions